<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:38:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351150</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351150</link>
      <description>EUVD-2026-351150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351150</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56020</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56020</link>
      <description>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56020</guid>
    </item>
    <item>
      <title>GHSA-23xj-gfh3-wf2h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-23xj-gfh3-wf2h</link>
      <description>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-23xj-gfh3-wf2h</guid>
    </item>
    <item>
      <title>VA-26-169-02 — Webmin multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/va-26-169-02</link>
      <description>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202. Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern. Webmin accepts basic authentication without session cookies when an attacker provides the &amp;#39;User-Agent: webmin&amp;#39; header, allowing bypass of additional MFA requirements. Fixed in 2.640.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202. Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern. Webmin accepts basic authentication without session cookies when an attacker provides the &amp;#39;User-Agent: webmin&amp;#39; header, allowing bypass of additional MFA requirements. Fixed in 2.640.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/va-26-169-02</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2014 — Webmin: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2014</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2014</guid>
    </item>
  </channel>
</rss>
